
On 18 July 2025, Uganda’s Personal Data Protection Office (PDPO) ruled in Ssekamwa Frank & 3 others v. Google LLC that Uganda’s data protection compliance obligations apply to any entity—anywhere in the world—that handles the personal data of Ugandan citizens.
Key Takeaways
Physical presence in Uganda is not required. If you collect or process Ugandan citizens’ data, Ugandan law applies to you.
Cross-Border Transfer Implications
• No prior PDPO approval is required for each transfer or offshore storage.
• Every controller or processor must maintain detailed records of the legal basis, safeguards, and justification for each transfer.
• These records must be available during audits, compliance checks, or investigations.
In this case, Google was found in violation for failing to show a lawful basis and compliance framework for transfers of Ugandan data abroad. It was ordered to:
• Register with the PDPO,
• Appoint a data protection officer,
• Submit cross-border compliance documentation within 30 days.
Why This Matters
This decision adds Uganda to the growing list of jurisdictions—like the EU (GDPR) and Nigeria—asserting extraterritorial jurisdiction over personal data and imposing strict accountability for cross-border data flows.
For global businesses, the message is clear: data sovereignty is borderless, but compliance is not optional.
Source: https://lnkd.in/eSHT54qk
